Need help for environement Security with RAC system
Hello ,
My environment :
O.S: Oracle Linux Server release 6.5
Grid:11.2.0.4
D.B:11.2.0.4
RAC system 2 node.
Our company make a security assessment and this is the O.S Recommendations Actions:
1-The vulnerability allows a remote attacker to enumerate all accounts on the system. The vulnerability exists due to a logical error in auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c files when processing authentication requests. A remote attacker can send a specially crafted chain of packets and monitor behavior of openssh server to determine presence of a valid username. The server will drop connection upon receiving a malformed authentication packets if the username is valid.